Microsoft's GitHub account allegedly hacked, 500GB stolen

栏目: IT技术 · 发布时间: 4年前

内容简介:A hacker claims to have stolen over 500GB of data from Microsoft's private GitHub repositories, BleepingComputer has learned.This evening, a hacker going by the name Shiny Hunters contacted BleepingComputer to tell us they had hacked into the Microsoft Git

Microsoft's GitHub account allegedly hacked, 500GB stolen

A hacker claims to have stolen over 500GB of data from Microsoft's private GitHub repositories, BleepingComputer has learned.

This evening, a hacker going by the name Shiny Hunters contacted BleepingComputer to tell us they had hacked into the Microsoft GitHub account, gaining full access to the software giant's 'Private' repositories.

Microsoft's GitHub account allegedly hacked, 500GB stolen
Actor's proof of access to Microsoft's private GitHub repos

The individual told us that they then downloaded 500GB of private projects and initially planned on selling it, but has now decided to leak it for free

Based on the file stamps in the leaked files, the breach may have occurred on March 28th, 2020.

Microsoft's GitHub account allegedly hacked, 500GB stolen
Leaked data listing showing the breach date

Shiny Hunters told BleepingComputer he no longer has access to the account.

Private repositories leaked

As a teaser, the hacker offered 1GB of files on a hacker forum for registered members to use site 'credits' to gain access to the leaked data.

As some of the leaked files contain Chinese text or references to latelee.org or Chinese text, other threat actors on the forum do not feel that the data is real.

In a directory listing and samples of other private repositories sent to BleepingComputer, the stolen data appears to be mostly code samples, test projects, an eBook, and other generic items.

Some private repositories look a bit more interesting such as ones named some 'wssd cloud agent', a The Rust/WinRT language projection', and a 'PowerSweep' PowerShell project.

Overall, from what was shared, there does not appear to be anything significant for Microsoft to worry about, such as Windows or Office source code.

Cyber intelligence firm Under the Breach, who saw the leak on the hacker forum, also does not think there is much to worry about.

They did express concern that private API keys or passwords could have accidentally been left behind in some of the private repositories like other developers have done in the past.

Microsoft's GitHub account allegedly hacked, 500GB stolen

Microsoft employee Sam Smith replied to Under the Breach's tweet stating that he thought the leak was fake as "Msft has a “rule” that GitHub repos must be public within 30 days."

BleepingComputer has contacted Microsoft to confirm if these are indeed legitimate files but have not received a reply.

This is a developing story.


以上所述就是小编给大家介绍的《Microsoft's GitHub account allegedly hacked, 500GB stolen》,希望对大家有所帮助,如果大家有任何疑问请给我留言,小编会及时回复大家的。在此也非常感谢大家对 码农网 的支持!

查看所有标签

猜你喜欢:

本站部分资源来源于网络,本站转载出于传递更多信息之目的,版权归原作者或者来源机构所有,如转载稿涉及版权问题,请联系我们

Spring框架高级编程

Spring框架高级编程

约翰逊 / 蒋培 / 机械工业出版社 / 2006-4 / 59.00元

Spring框架是主要的开源应用程序开发框架,它使得Java/J2EE开发更容易、效率更高。本书不仅向读者展示了Spring能做什么?而且揭示了Spring完成这些功能的原理,解释其功能和动机,以帮助读者使用该框架的所有部分来开发成功的应用程序。本书涵盖Spring的所有特性,并且演示了如何将其构成一个连贯的整体,帮助读者理解Spring方法的基本原理、何时使用Sping以及如何效仿最佳实践。所有......一起来看看 《Spring框架高级编程》 这本书的介绍吧!

JS 压缩/解压工具
JS 压缩/解压工具

在线压缩/解压 JS 代码

CSS 压缩/解压工具
CSS 压缩/解压工具

在线压缩/解压 CSS 代码

图片转BASE64编码
图片转BASE64编码

在线图片转Base64编码工具